VulnerabilityModified
CVE-2023-32390
The issue was addressed with improved checks.
LOW 2.4EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup.
- CVSS 3.1
- 2.4 LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT213757Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213758Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213764Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213761
- https://support.apple.com/en-us/HT213757Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213758Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213764Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213761
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.